{"api_version":"1","generated_at":"2026-08-22T04:33:46+00:00","cve":"CVE-2026-72064","urls":{"html":"https://cve.report/CVE-2026-72064","api":"https://cve.report/api/cve/CVE-2026-72064.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72064","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72064"},"summary":{"title":"net: mana: Sync page pool RX frags for CPU","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Sync page pool RX frags for CPU\n\nMANA allocates RX buffers from page pool fragments when frag_count is\ngreater than 1. In that case the buffers remain DMA mapped by page pool\nand the RX completion path does not call dma_unmap_single(). As a result,\nthe implicit sync-for-CPU normally performed by dma_unmap_single() is\nmissing before the packet data is passed to the networking stack.\n\nThis breaks RX on configurations which require explicit DMA syncing, for\nexample when booted with swiotlb=force.\n\nFix this by recording the page pool page and DMA sync offset when the RX\nbuffer is allocated, and syncing the received packet range for CPU access\nbefore handing the RX buffer to the stack.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:21:16","updated_at":"2026-08-17 06:18:04"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/bc650dd5ce6434286b96e2b26a41af81f679cc7c","name":"https://git.kernel.org/stable/c/bc650dd5ce6434286b96e2b26a41af81f679cc7c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c72a0f09c57f92113df69f9b902d11c9e4b132f5","name":"https://git.kernel.org/stable/c/c72a0f09c57f92113df69f9b902d11c9e4b132f5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72064","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72064","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 730ff06d3f5cc2ce0348414b78c10528b767d4a3 bc650dd5ce6434286b96e2b26a41af81f679cc7c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 730ff06d3f5cc2ce0348414b78c10528b767d4a3 c72a0f09c57f92113df69f9b902d11c9e4b132f5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72064","cve":"CVE-2026-72064","epss":"0.005530000","percentile":"0.435850000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c","include/net/mana/mana.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"bc650dd5ce6434286b96e2b26a41af81f679cc7c","status":"affected","version":"730ff06d3f5cc2ce0348414b78c10528b767d4a3","versionType":"git"},{"lessThan":"c72a0f09c57f92113df69f9b902d11c9e4b132f5","status":"affected","version":"730ff06d3f5cc2ce0348414b78c10528b767d4a3","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c","include/net/mana/mana.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.18"},{"lessThan":"6.18","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"6.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.18","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Sync page pool RX frags for CPU\n\nMANA allocates RX buffers from page pool fragments when frag_count is\ngreater than 1. In that case the buffers remain DMA mapped by page pool\nand the RX completion path does not call dma_unmap_single(). As a result,\nthe implicit sync-for-CPU normally performed by dma_unmap_single() is\nmissing before the packet data is passed to the networking stack.\n\nThis breaks RX on configurations which require explicit DMA syncing, for\nexample when booted with swiotlb=force.\n\nFix this by recording the page pool page and DMA sync offset when the RX\nbuffer is allocated, and syncing the received packet range for CPU access\nbefore handing the RX buffer to the stack."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in the MANA Ethernet RX completion path (MSI-X/NAPI → mana_process_rx_cqe → mana_refill_rx_oob → mana_rx_skb) on Azure/cloud VMs; any remote host that can send IP traffic to the MANA interface drives packet reception before authentication or local privilege checks.\nAC:L - On deployments where DMA needs explicit CPU sync (e.g. swiotlb=force or non-coherent DMA), every received frame on the default standard-MTU page-pool-fragment path (frag_count>1) deterministically skips sync; the attacker only sends network packets with no race, layout gamble, or timing window.\nPR:N - Exploitation requires no credentials or local access; the vulnerable code runs in hardware interrupt/NAPI context on inbound packets and is not gated by capabilities, netlink, ioctl, or user namespaces.\nUI:N - Packet reception and handoff to the networking stack occur automatically once the MANA interface is up; no victim mount, click, or other administrative action is required beyond normal network operation.\nS:U - Impact is confined to incorrect/stale packet data processed inside the same guest kernel and network stack; it does not cross a VM-host, IOMMU, or other separate security boundary.\nC:H - Without dma_sync_for_cpu the CPU can read stale cache or bounce-buffer contents for the full received length (up to MTU) instead of hardware-written data, disclosing prior RX buffer or unrelated DMA residue to the stack, XDP, or applications.\nI:H - The skb handed upward can contain bytes that differ from the frame the NIC actually wrote, corrupting protocol parsing and application-visible payload integrity across the entire packet, not just a bounded tail region.\nA:H - On configurations requiring explicit DMA syncing the driver commit reports RX is broken entirely; a remote sender can repeatedly trigger the faulty path and deny reliable receive on the MANA interface."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:39:55.896Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/bc650dd5ce6434286b96e2b26a41af81f679cc7c"},{"url":"https://git.kernel.org/stable/c/c72a0f09c57f92113df69f9b902d11c9e4b132f5"}],"title":"net: mana: Sync page pool RX frags for CPU","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72064","datePublished":"2026-08-15T05:52:18.069Z","dateReserved":"2026-08-09T03:40:39.903Z","dateUpdated":"2026-08-17T05:39:55.896Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:21:16","lastModifiedDate":"2026-08-17 06:18:04","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72064","Ordinal":"1","Title":"net: mana: Sync page pool RX frags for CPU","CVE":"CVE-2026-72064","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72064","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Sync page pool RX frags for CPU\n\nMANA allocates RX buffers from page pool fragments when frag_count is\ngreater than 1. In that case the buffers remain DMA mapped by page pool\nand the RX completion path does not call dma_unmap_single(). As a result,\nthe implicit sync-for-CPU normally performed by dma_unmap_single() is\nmissing before the packet data is passed to the networking stack.\n\nThis breaks RX on configurations which require explicit DMA syncing, for\nexample when booted with swiotlb=force.\n\nFix this by recording the page pool page and DMA sync offset when the RX\nbuffer is allocated, and syncing the received packet range for CPU access\nbefore handing the RX buffer to the stack.","Type":"Description","Title":"net: mana: Sync page pool RX frags for CPU"}]}}}